Записи apostrophecms
17 опубликованных записей вендора apostrophecms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-287 Improper Authentication1
- CWE-613 Insufficient Session Expiration1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-25979Эксплойта нет | Apostrophe - Insufficient Session Expirationapostrophecms · apostrophecms · CWE-613 | Критическая9,8 | — | 1,1 % | 8 нояб. 2021 г. |
39Наблюдать | CVE-2026-32731Proof of concept | ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extractionapostrophecms · import-export · CWE-22 | Критическая9,9 | — | 0,6 % | 18 мар. 2026 г. |
34Наблюдать | CVE-2026-35569Эксплойта нет | ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMSapostrophecms · apostrophecms · CWE-79 | Высокая8,7 | — | 0,4 % | 15 апр. 2026 г. |
32Наблюдать | CVE-2026-32730Эксплойта нет | ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middlewareapostrophecms · apostrophecms · CWE-287 | Высокая8,1 | — | 0,5 % | 18 мар. 2026 г. |
30Наблюдать | CVE-2022-25887Эксплойта нет | Regular Expression Denial of Service (ReDoS)apostrophecms · sanitize-html · CWE-1333 | Высокая7,5 | — | 1,5 % | 30 авг. 2022 г. |
24Наблюдать | CVE-2016-1000237Эксплойта нет | sanitize-html before 1.4.3 has XSS.apostrophecms · sanitize-html · CWE-79 | Средняя6,1 | — | 0,8 % | 23 янв. 2020 г. |
24Наблюдать | CVE-2026-40186Эксплойта нет | ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elementsapostrophecms · apostrophecms · CWE-79 | Средняя6,1 | — | 0,3 % | 15 апр. 2026 г. |
24Наблюдать | CVE-2014-125128Эксплойта нет | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Средняя6,1 | — | 0,3 % | 8 сент. 2025 г. |
24Наблюдать | CVE-2019-25225Эксплойта нет | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).apostrophecms · sanitize-html · CWE-79 | Средняя6,1 | — | 0,3 % | 8 сент. 2025 г. |
22Наблюдать | CVE-2021-26539Эксплойта нет | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attackeapostrophecms · sanitize-html | Средняя5,3 | — | 2,0 % | 8 февр. 2021 г. |
22Наблюдать | CVE-2021-26540Эксплойта нет | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when apostrophecms · sanitize-html | Средняя5,3 | — | 1,8 % | 8 февр. 2021 г. |
21Наблюдать | CVE-2024-21501Эксплойта нет | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attriapostrophecms · sanitize-html · CWE-200 | Средняя5,3 | — | 1,0 % | 24 февр. 2024 г. |
21Наблюдать | CVE-2026-33888Эксплойта нет | ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST APIapostrophecms · apostrophecms · CWE-200 | Средняя5,3 | — | 0,5 % | 15 апр. 2026 г. |
21Наблюдать | CVE-2021-25978Эксплойта нет | Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Javapostrophecms · apostrophecms · CWE-79 | Средняя5,4 | — | 0,5 % | 7 нояб. 2021 г. |
21Наблюдать | CVE-2026-39857Эксплойта нет | Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictionsapostrophecms · apostrophecms · CWE-200 | Средняя5,3 | — | 0,4 % | 15 апр. 2026 г. |
21Наблюдать | CVE-2026-33889Эксплойта нет | ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Contextapostrophecms · apostrophecms · CWE-79 | Средняя5,4 | — | 0,3 % | 15 апр. 2026 г. |
14Наблюдать | CVE-2026-33877Эксплойта нет | ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpointapostrophecms · apostrophecms · CWE-208 | Низкая3,7 | — | 0,3 % | 15 апр. 2026 г. |
- CVE-2021-2597939Наблюдать
Apostrophe - Insufficient Session Expiration
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apostrophecms · apostrophecms8 нояб. 2021 г.
- CVE-2026-3273139Наблюдать
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
КритическаяCVSS 9,9Proof of conceptEPSS 1 %apostrophecms · import-export18 мар. 2026 г.
- CVE-2026-3556934Наблюдать
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %apostrophecms · apostrophecms15 апр. 2026 г.
- CVE-2026-3273032Наблюдать
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %apostrophecms · apostrophecms18 мар. 2026 г.
- CVE-2022-2588730Наблюдать
Regular Expression Denial of Service (ReDoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apostrophecms · sanitize-html30 авг. 2022 г.
- CVE-2016-100023724Наблюдать
sanitize-html before 1.4.3 has XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %apostrophecms · sanitize-html23 янв. 2020 г.
- CVE-2026-4018624Наблюдать
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
СредняяCVSS 6,1Эксплойта нетEPSS 0 %apostrophecms · apostrophecms15 апр. 2026 г.
- CVE-2014-12512824Наблюдать
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 0 %apostrophecms · sanitize-html8 сент. 2025 г.
- CVE-2019-2522524Наблюдать
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 0 %apostrophecms · sanitize-html8 сент. 2025 г.
- CVE-2021-2653922Наблюдать
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacke
СредняяCVSS 5,3Эксплойта нетEPSS 2 %apostrophecms · sanitize-html8 февр. 2021 г.
- CVE-2021-2654022Наблюдать
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when
СредняяCVSS 5,3Эксплойта нетEPSS 2 %apostrophecms · sanitize-html8 февр. 2021 г.
- CVE-2024-2150121Наблюдать
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attri
СредняяCVSS 5,3Эксплойта нетEPSS 1 %apostrophecms · sanitize-html24 февр. 2024 г.
- CVE-2026-3388821Наблюдать
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
СредняяCVSS 5,3Эксплойта нетEPSS 1 %apostrophecms · apostrophecms15 апр. 2026 г.
- CVE-2021-2597821Наблюдать
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious Jav
СредняяCVSS 5,4Эксплойта нетEPSS 0 %apostrophecms · apostrophecms7 нояб. 2021 г.
- CVE-2026-3985721Наблюдать
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
СредняяCVSS 5,3Эксплойта нетEPSS 0 %apostrophecms · apostrophecms15 апр. 2026 г.
- CVE-2026-3388921Наблюдать
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
СредняяCVSS 5,4Эксплойта нетEPSS 0 %apostrophecms · apostrophecms15 апр. 2026 г.
- CVE-2026-3387714Наблюдать
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %apostrophecms · apostrophecms15 апр. 2026 г.